writeups.xyz writeups.xyz / NTLM

Title Vulnerabilities Programs Authors
NTLM Credential Theft in Python Windows Applications
Drop the Mic (CVE-2019-1166)
Hello: I’m your Domain Admin and I want to authenticate against you
Mintty NTLM Leak - CVE-2023-50627
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes (CVE-2023-35636)
CVE-2023-50916: Authentication Coercion Vulnerability in Kyocera Device Manager
Behind the Query: Unearthing NTLM Hashes with SQL Injection
GPOddity: Exploiting Active Directory GPOs Through NTLM Relaying, And More!
Site Takeover via SCCM’s AdminService API
From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API
Protected Users: you thought you were safe uh?
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
LocalPotato - When Swapping The Context Leads You To SYSTEM